Back to search
CVE-2014-3476
Published: Jun 17, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
SUSE-SU-2014:0848
vendor-advisory
x_refsource_SUSE
59547
third-party-advisory
x_refsource_SECUNIA
68026
vdb-entry
x_refsource_BID
https://bugs.launchpad.net/keystone/+bug/1324592
x_refsource_CONFIRM
57886
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now